Bug 2376221 (CVE-2025-53367) - CVE-2025-53367 djvulibre: DjVuLibre out of bounds write
Summary: CVE-2025-53367 djvulibre: DjVuLibre out of bounds write
Keywords:
Status: NEW
Alias: CVE-2025-53367
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2376248 2376249 2376251 2376253 2376255 2376252 2376254
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-03 22:01 UTC by OSIDB Bzimport
Modified: 2025-07-03 23:16 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-07-03 22:01:14 UTC
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.


Note You need to log in before you can comment on or make changes to this bug.